India’s Star Health confirms data breach after cybercriminals post customers’ health data online

Date:

Share post:


Star Health and Allied Insurance, one of the largest health insurance firms in India, has confirmed it was the target of a “malicious cyberattack,” some two weeks after cybercriminals claimed to post customers’ health records and other sensitive data online.

The Chennai-headquartered insurance giant told TechCrunch in a statement Wednesday that the cyberattack resulted in “unauthorized and illegal access to certain data,” though it stated its operations remained unaffected and services continued.

“A thorough and rigorous forensic investigation, led by independent cybersecurity experts, is underway, and we are working closely with government and regulatory authorities at every stage of this investigation, including by duly reporting the incident to the insurance and cybersecurity regulatory authorities apart from filing a criminal complaint,” the company said in its statement.

When asked by TechCrunch, Star Health would not say if the data breach included customers’ data.

Last month, a hacker group created chatbots on Telegram that leaked the alleged personal data belonging to 31 million Star Health policyholders and over 5.8 million insurance claims. The data included full names, phone numbers, and home addresses, as well as medical reports and insurance claims of individuals. The hackers also shared copies of customer ID cards and individuals’ tax details.

Star Health told TechCrunch at the time that the company was “investigating” the alleged theft.

Shortly after the hackers’ Telegram bots came to light, Star Health filed a legal complaint with the Madras High Court against Telegram for hosting the chatbots. The insurer also named Cloudflare in its lawsuit for its role in hosting the hacker group’s websites on its service.

India’s CERT-In told TechCrunch earlier that it was “already in process of taking appropriate action with the concerned authority.”

Details of the breach, and how the hackers obtained potentially millions of customers’ data, remain unclear.

The hackers’ website, used to publicize the Telegram bots sharing the allegedly stolen person data, includes a video allegedly showing screenshots and conversations between Star Health CISO Amarjeet Khanuja and the hacker group. TechCrunch is not linking to the site as it contains personally identifiable information.

The role of the company’s CISO in the cyberattack, if at all, is not yet known.

“We also want to categorically mention that our CISO has been duly co-operating in the investigation, and we have not arrived at any finding of wrongdoing by him till date. We request that his privacy be respected as we know that the threat actor is trying to create panic,” the insurer said Wednesday.

TechCrunch asked specific questions, including whether the insurer can confirm who accessed the data, whether it was an insider or a malicious intruder, and if it knows and can confirm what has been accessed or taken already. The insurer would not say.

Star Health, which provides health, personal accident, and overseas and travel insurance, has a network of more than 14,000 hospitals and over 850 branch offices across India. Star Health says on its website that it has provided health insurance coverage to 170 million individuals.



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

Did that startup founder really work through his wedding?

Thoughtly co-founder Casey Mackrell had a big week. First, he got married. Then, he went viral. At his...

Bridgit Mendler’s Northwood makes ground station connection with Planet Labs in key test

Northwood Space, the startup founded by former Disney star Bridgit Mendler, nailed a key test last week...

You can now buy songs from Green Day’s ‘Dookie’ in lo-fi formats like doorbell chime and wax cylinder

To celebrate the 30th anniversary of Green Day’s classic pop-punk album “Dookie,” Los Angeles art studio Brain...

Russia is banning Discord, an app its military uses

Russia is banning chat platform Discord, the Washington Post reports. The app joins platforms like Facebook and...

TezLab launches new AI-powered ‘car reports’ for Tesla and Rivian EVs

Modern connected vehicles, and especially EVs, generate a lot of data. But automakers don’t often give owners...

After winning Nobel for foundational AI work, Geoffrey Hinton says he’s proud Ilya Sutskever ‘fired Sam Altman’

Geoffrey Hinton accepted a Nobel Prize this week, recognizing the foundational work on artificial neural networks that...

This Week in AI: Tech giants embrace synthetic data

Hiya, folks, welcome to TechCrunch’s regular AI newsletter. If you want this in your inbox every Wednesday,...

Streamer Plex rolls out movie and TV show reviews

Following its $40 million fundraise at the beginning of this year, streaming media company Plex announced on Wednesday it’s...